Skip to content

chore: enable OIDC npm publishing (#1682) #79

chore: enable OIDC npm publishing (#1682)

chore: enable OIDC npm publishing (#1682) #79

name: release-please
on:
push:
branches:
- main
workflow_dispatch:
permissions:
id-token: write # Required for OIDC
contents: read
jobs:
release-please:
runs-on: ubuntu-latest
outputs:
release_created: ${{ steps.release.outputs.release_created }}
permissions:
contents: write
pull-requests: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1
with:
egress-policy: audit
- uses: googleapis/release-please-action@a02a34c4d625f9be7cb89156071d8567266a2445 # v4.2.0
id: release
with:
config-file: release-please-config.json
manifest-file: .release-please-manifest.json
npm-publish:
needs: release-please
if: ${{ needs.release-please.outputs.release_created }}
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1
with:
egress-policy: audit
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 24 # npm >= 11.5.1
registry-url: 'https://registry.npmjs.org'
- run: npm publish --provenance --access public